Back to Tsumi

Privacy Policy

Last updated: March 23, 2026

Your privacy matters to us. This policy explains what information Tsumi collects, how we use it, and what choices you have. We keep things simple: we collect only what we need and never sell your data.

Data Controller

Tsumi is operated by an individual data controller based in Malta. For any privacy-related questions or data subject requests, you can reach us at:

privacy@tsumi.gg

Information We Collect

Account Information

When you create an account via Google or Discord, we receive your display name, email address, and profile picture from those services. We also store your chosen username and any bio you provide.

Content You Create

Reviews, discussions, replies, votes, and community memberships you create on Tsumi are stored in our database. Your public posts (reviews, discussions, display name, bio) are visible to other users and the general public.

Authentication Data

We store OAuth identifiers and session tokens required to keep you signed in. See our Cookie Policy for details on cookies used.

Analytics

We use Vercel Web Analytics, which is cookieless and collects only aggregated, non-personally-identifiable statistics. IP-based hashes are discarded within 24 hours. No analytics cookies are set.

Advertising Measurement

We use Google Ads conversion tracking (via Google tag / gtag.js) to measure whether our advertising campaigns lead to visits or sign-ups. This only sets cookies on your device if you accept in our cookie consent banner. We use Google Consent Mode v2, meaning no advertising data is collected without your explicit consent. We do not use this data for profiling or retargeting.

How We Use Your Information

  • To provide and maintain your account
  • To display your reviews, discussions, and profile to other users
  • To personalize your feed based on communities you join and users you follow
  • To send you notifications about activity on your posts
  • To enforce our Community Guidelines and Terms of Service
  • To improve Tsumi and fix bugs via aggregated analytics

We do not use your data for marketing, advertising, profiling, newsletters, or automated decision-making.

What We Don't Do

  • We never sell your personal data to third parties
  • We never share your email address publicly
  • We don't use your data for targeted advertising or retargeting
  • We don't track you across other websites (Google Ads cookies only measure conversions from our own ads)
  • We don't use automated decision-making or profiling

Legal Basis for Processing (GDPR)

Tsumi is operated from Malta, an EU member state. We process your personal data under the following legal bases:

Contractual Necessity (Article 6(1)(b))

Processing necessary to provide the Tsumi service you signed up for: creating and maintaining your account, storing and displaying your content, personalizing your feed, delivering notifications, and authentication. This covers your account data, profile, reviews, votes, community memberships, and session tokens.

Legitimate Interest (Article 6(1)(f))

Processing necessary for our legitimate interests: aggregated site analytics (via Vercel Web Analytics, cookieless), improving the platform, fixing bugs, and preventing abuse. These interests do not override your rights given the minimal, non-identifying nature of the data processed.

Consent (Article 6(1)(a))

Google Ads conversion cookies are only set after you give explicit consent via our cookie banner. You can withdraw consent at any time by clearing your cookies or local storage for tsumi.gg.

Legal Obligation (Article 6(1)(c))

Processing necessary to comply with legal requirements, such as responding to lawful requests from authorities.

Data Recipients & Third-Party Services

Your data may be shared with or processed by the following third parties:

Google & Discord (Independent Controllers)

If you sign in with Google or Discord, these providers handle authentication independently under their own privacy policies. We receive only your display name, email, and avatar from the OAuth flow. See Google's Privacy Policy and Discord's Privacy Policy.

Google Ads (Data Processor)

If you consent to advertising cookies, Google receives conversion data (that you visited or signed up on Tsumi after clicking an ad). Google processes this data under their Ads Data Processing Terms. No conversion data is sent without your consent (Google Consent Mode v2).

Vercel (Data Processor)

Our hosting and analytics provider. Vercel processes data on our behalf under their Data Processing Agreement, which includes EU Standard Contractual Clauses.

The Public

Your display name, bio, profile picture, reviews, and discussions are publicly visible to anyone who visits Tsumi. Your email address is never shared publicly.

International Data Transfers

Your data is transferred to US-based providers (Google, Discord, Vercel), all of which are certified under the EU-US Data Privacy Framework (DPF). Vercel's DPA additionally includes EU Standard Contractual Clauses as a safeguard. These mechanisms ensure your data receives an adequate level of protection as required by GDPR.

Data Storage & Security

Your data is stored securely on servers with encryption in transit and at rest. We use industry-standard security practices to protect your information. Passwords are hashed and never stored in plain text.

Data Retention

We retain your personal data only for as long as necessary to provide the service:

Account data: Retained while your account is active, plus a 30-day grace period after deletion request for accidental recovery.

Content: Retained while your account is active. Upon account deletion, reviews are anonymized (author replaced with “Deleted User”) to preserve discussion threads, unless you request full deletion.

Session tokens: Automatically expire after logout or a period of inactivity.

Analytics hashes: Automatically discarded by Vercel within 24 hours.

Server logs: Retained for up to 90 days, then auto-deleted.

Your Rights

Under the GDPR and applicable privacy laws, you have the following rights. To exercise any of them, email us at privacy@tsumi.gg. We will respond within one calendar month.

Right of Access: Request a copy of the personal data we hold about you, provided in a structured format (JSON).

Right to Rectification: Request correction of inaccurate or incomplete data. You can also edit your profile and reviews directly through the platform.

Right to Erasure: Request deletion of your personal data. Upon deletion, your profile data is removed and reviews are anonymized. You may request full deletion of all content instead.

Right to Restrict Processing: Request that we limit how we use your data while a dispute is resolved.

Right to Data Portability: Request your data in a structured, machine-readable format (JSON export of your profile, reviews, votes, and memberships).

Right to Object: Object to processing based on legitimate interest (analytics).

Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.

Supervisory Authority

If you are unsatisfied with how we handle your data or your request, you have the right to lodge a complaint with Malta's data protection authority:

Information and Data Protection Commissioner (IDPC)

Floor 2, Airways House, High Street, Sliema SLM 1549, Malta

Phone: +356 2328 7100

Email: idpc.info@idpc.org.mt

Website: idpc.org.mt

Cookies

Tsumi uses strictly necessary cookies for authentication and session management (exempt from consent). We also use Google Ads conversion cookies to measure ad effectiveness — these are only set with your explicit consent via our cookie banner. Vercel Web Analytics is fully cookieless. See our Cookie Policy for full details.

Children's Privacy

Tsumi is not intended for children under 13 (the digital age of consent in Malta). We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time. When we make significant changes, we'll notify users through the platform. Continued use of Tsumi after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy or your data? Email us at privacy@tsumi.gg or reach out through our Help page.